Topology and Requirements: Transparent HA Mode With Trunks Parent topic

You can configure Transparent HA mode with trunk links. You should be aware of certain requirements and the topology for this deployment mode.
You can create trunk links using LACP port aggregation in environments where higher bandwidth for data ingress and data egress is required. When LACP is enabled, Deep Discovery Web Inspector automatically creates a two-port trunk for data ingress and a two-port trunk for data egress on each of the two HA nodes.

Topology

topology_transparent_001.png

Transparent HA with trunk links

Requirements

You should understand the following requirements that are dependent on how Deep Discovery Web Inspector IP addressing works under various scenarios for VLAN trunk links including the following:
  1. How IP addressing works under the native VLAN of the trunk link:
    Case 1: Traffic under the native VLAN going out of the switch to Deep Discovery Web Inspector does not carry the native VLAN ID.
    Requirement: When performing the initial deployment, you should disable the VLAN ID on the egress port.
    Case 2: Traffic under the native VLAN going out of the switch to Deep Discovery Web Inspector carries the native VLAN ID.
    Requirement: When performing the initial deployment, you should enable the VLAN ID on the egress port, and the VLAN ID must set to the native VLAN ID.
  2. How IP addressing works under a normal trunk VLAN.
    Requirement: When performing the initial deployment, you should enable the VLAN ID on the egress port, and the VLAN ID must set to the normal trunk VLAN ID.
Important
Important
  • You must ensure that the IP address of the Deep Discovery Web Inspector bridge egress interface (br0) can access the Internet.
  • If some clients and the internal web servers are deployed in the same VLAN and the IP address of the egress port of the appliance is not in the same VLAN, clients might not be able to access the internal HTTP server after the VLAN converges to the egress port VLAN.
  • In a trunk link, all traffic from ingress can carry different VLAN tags. All these VLAN tags will converge to the one VLAN (native VLAN/normal VLAN) of the egress port to access to the Internet.